Exploited in the wild Langflow rce IBM ai-ml
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
CVE Tools coverage
VulnCheck reports active exploitation of CVE-2026-0768, a critical remote code execution vulnerability in IBM's AI platform Langflow. With a CVSS score of 9.8, the flaw enables attackers to execute arbitrary code on internet-exposed instances, leading to credential theft, lateral movement, and data exfiltration. Despite Langflow's low-code nature simplifying AI agent creation, its default configurations often leave it vulnerable to widespread scanning and persistent backdoor installation by global threat actors.